TL;DR

  • The Tectonic exploit used a sharply inflated TONIC price to support tens of millions of dollars in borrowing.
  • Cronos rolled back the chain, reversing $68.7 million in reported borrowing that had remained on the network.
  • About $6 million reached Ethereum before the halt, while the final loss and any depositor impact remain unresolved.

Cronos rolled back its entire blockchain to undo an exploit on Tectonic, its largest lending protocol, after an attacker used an inflated token price to borrow from the platform. Independent on-chain researcher Weilin Li first estimated the borrowing at $75 million; TRM Labs later cited the same figure. The network resumed block production on August 31, one day after validators halted it during the attack.

The rollback recovered most of the funds that had remained on Cronos, but a portion had already reached Ethereum before the halt, beyond the chain’s reach, according to blockchain intelligence firm TRM Labs.

Tectonic had warned users not to interact with the protocol until it said doing so was safe.

How the TONIC price attack worked

Tectonic allows users to deposit crypto as collateral and borrow other assets against it. The protocol accepted TONIC, its own governance token, as collateral with a 20% collateral factor. In simple terms, every $100 of value recognized by the system could support about $20 of borrowing.

TONIC traded on a thin market, making the collateral arrangement easy to move. TRM said the token recorded about $305,000 in trading volume during the week before the attack.

On August 30, the attacker pushed TONIC’s price up about 100-fold in roughly 20 minutes, then deposited the inflated tokens and borrowed assets with deeper markets from Tectonic’s pools.

TONIC’s price moved cheaply because so little of it traded, and Tectonic’s lending system accepted that price at face value.

Source: CoinGecko.com

Cronos chain rollback

Cronos halted after block 90,907,150 at 14:32:47 UTC on August 30, TRM reported. The network’s software caps its validator set at 100, small enough for the group to coordinate a halt within minutes.

Validators restarted Cronos on August 31 by rolling the chain back to a point before the Tectonic attack, discarding every transaction recorded after that point and returning the network to its earlier state. That reversed the $68.7 million in reported borrowing that had stayed on Cronos. But the rollback did not target the attacker specifically: it erased every transaction recorded after the restored point, whether or not it had anything to do with the exploit.

TRM said about $6 million reached Ethereum before the halt and was exchanged into roughly 2,500 ETH. Those assets survived the rollback because Ethereum keeps its own separate transaction history. Cronos cannot alter those records.

The rollback also accounts for a separate data point: Tectonic’s total value locked, which fell to roughly $3 million during the exploit, had returned to close to its pre-exploit level of about $121 million by September 1. Restoring the chain to a point before the attack undid the transactions that had drained it.

No final loss report

Estimates of the loss have moved as new information emerged. Li initially put the borrowing at $66 million, then revised the figure to $75 million after identifying a second attacker-controlled address. A separate on-chain analysis placed the total higher, at $119.5 million.

The attacker withdrew a mix of assets, including USDC, USDT, wrapped Bitcoin, and wrapped Ether, along with CRO, Cronos’s native token. No confirmed breakdown of the amounts exists. Neither Tectonic nor Cronos has published a final accounting. The gap between the estimates, along with any ultimate depositor losses, remains unresolved.

Tectonic’s total value locked fell from about $121.7 million on August 26 to roughly $3 million by August 31, according to TRM and CoinDesk — the low point before the rollback reversed it.

Source: DefiLlama.com

Price manipulation is becoming more common

TRM recorded 32 price-manipulation exploits in 2026, already the highest annual count in its data. It said this method now accounts for about one in eight crypto attacks, compared with one in 17 in 2022.

The pattern puts pressure on lending protocols to consider how easily a collateral token’s market price can move. A functioning price feed cannot protect a pool when the underlying market is too small to support the borrowing it enables.

Tectonic users are waiting on two things now: when the protocol will confirm it’s safe to interact again, and whether any compensation or new controls will come before lending resumes.

LEAVE A REPLY

Please enter your comment!
Please enter your name here